Search CVE reports


Toggle filters

1 – 10 of 42780 results

Status is adjusted based on your filters.


CVE-2026-63650

Medium priority
Needs evaluation

OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field

1 affected package

openvpn

Package 24.04 LTS
openvpn Needs evaluation
Show less packages

CVE-2026-63649

Medium priority
Needs evaluation

The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via...

1 affected package

openvpn

Package 24.04 LTS
openvpn Needs evaluation
Show less packages

CVE-2026-49282

Medium priority
Needs evaluation

Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends validate the ID...

1 affected package

capstone

Package 24.04 LTS
capstone Needs evaluation
Show less packages

CVE-2026-49263

Medium priority
Needs evaluation

Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend accepts attacker-controlled raw WASM instruction bytes through the public `cs_disasm()` and `cs_disasm_iter()` APIs. For a large...

1 affected package

capstone

Package 24.04 LTS
capstone Needs evaluation
Show less packages

CVE-2026-46603

Medium priority
Needs evaluation

VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via...

1 affected package

golang-golang-x-image

Package 24.04 LTS
golang-golang-x-image Needs evaluation
Show less packages

CVE-2026-19879

Medium priority
Needs evaluation

A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method performs a silent narrowing cast from 16-bit Unicode characters to 8-bit bytes when writing HTTP response...

1 affected package

undertow

Package 24.04 LTS
undertow Needs evaluation
Show less packages

CVE-2026-19730

Medium priority

Not in release

The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many...

1 affected package

podman

Package 24.04 LTS
podman Not in release
Show less packages

CVE-2026-19720

Medium priority
Needs evaluation

[Unknown description]

1 affected package

inetutils

Package 24.04 LTS
inetutils Needs evaluation
Show less packages

CVE-2026-19617

Medium priority
Needs evaluation

A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration...

1 affected package

lvm2

Package 24.04 LTS
lvm2 Needs evaluation
Show less packages

CVE-2026-18697

Medium priority

Not in release

(An issue in MongoDB Server's aggregation framework could allow an unau ...)

1 affected package

mongodb

Package 24.04 LTS
mongodb Not in release
Show less packages